nilsteampassnet/teampass
teampass
Activity
- Latest release
- 3w ago
- Total releases
- 11
- Cadence
- ~1.0 years
- Last 12 months
- 2
Reach
- Stars
- —
Details
- License
- unknown
- First release
- Sep 21, 2014
| Version | Released | |
|---|---|---|
3.2.2.0
patch
|
3.2.2.0
patch
Dependencies (52)
+ 44 more
Changelog
Compare changes
|
|
3.2.0
minor
|
3.2.0
minor
Dependencies (51)
+ 43 more
Changelog
Compare changes
|
|
3.1.1
patch
3 CVEs
CVE-2024-50702
GHSA-7rm3-4w6j-8xx4
Dec 30, 2024
TeamPass mail_me operation authorization issue
Medium
Network
Low
Low
None
TeamPass before 3.1.3.1 does not properly check whether a mail_me (aka action_mail) operation is on behalf of an administrator or manager. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
3.0.10
3.1.0
3.1.1
Fixed in
3.1.3.1
References
Updated Dec 30, 2024 · Source: OSV.dev
CVE-2024-50703
GHSA-9wmc-988h-2mv2
Dec 30, 2024
TeamPass privileges issue
Critical
Network
Low
None
None
TeamPass before 3.1.3.1 does not properly prevent a user from acting with the privileges of a different user_id. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
3.0.10
3.1.0
3.1.1
Fixed in
3.1.3.1
References
Updated Dec 30, 2024 · Source: OSV.dev
CVE-2024-50701
GHSA-2697-96mv-3gfm
Dec 30, 2024
TeamPass does not properly check whether a folder is in a user's allowed folders list
Medium
Network
Low
Low
None
TeamPass before 3.1.3.1, when retrieving information about access rights for a folder, does not properly check whether a folder is in a user's allowed folders list that has been defined by an admin. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
3.0.10
3.1.0
3.1.1
Fixed in
3.1.3.1
References
Updated Dec 30, 2024 · Source: OSV.dev |
3.1.1
patch
Dependencies (38)
+ 30 more
Changelog
Compare changes
|
|
3.1.0
minor
3 CVEs
CVE-2024-50702
GHSA-7rm3-4w6j-8xx4
Dec 30, 2024
TeamPass mail_me operation authorization issue
Medium
Network
Low
Low
None
TeamPass before 3.1.3.1 does not properly check whether a mail_me (aka action_mail) operation is on behalf of an administrator or manager. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
3.0.10
3.1.0
3.1.1
Fixed in
3.1.3.1
References
Updated Dec 30, 2024 · Source: OSV.dev
CVE-2024-50703
GHSA-9wmc-988h-2mv2
Dec 30, 2024
TeamPass privileges issue
Critical
Network
Low
None
None
TeamPass before 3.1.3.1 does not properly prevent a user from acting with the privileges of a different user_id. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
3.0.10
3.1.0
3.1.1
Fixed in
3.1.3.1
References
Updated Dec 30, 2024 · Source: OSV.dev
CVE-2024-50701
GHSA-2697-96mv-3gfm
Dec 30, 2024
TeamPass does not properly check whether a folder is in a user's allowed folders list
Medium
Network
Low
Low
None
TeamPass before 3.1.3.1, when retrieving information about access rights for a folder, does not properly check whether a folder is in a user's allowed folders list that has been defined by an admin. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
3.0.10
3.1.0
3.1.1
Fixed in
3.1.3.1
References
Updated Dec 30, 2024 · Source: OSV.dev |
3.1.0
minor
Dependencies (33)
+ 25 more
Changelog
Compare changes
|
|
3.0.10
patch
3 CVEs
CVE-2024-50702
GHSA-7rm3-4w6j-8xx4
Dec 30, 2024
TeamPass mail_me operation authorization issue
Medium
Network
Low
Low
None
TeamPass before 3.1.3.1 does not properly check whether a mail_me (aka action_mail) operation is on behalf of an administrator or manager. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
3.0.10
3.1.0
3.1.1
Fixed in
3.1.3.1
References
Updated Dec 30, 2024 · Source: OSV.dev
CVE-2024-50703
GHSA-9wmc-988h-2mv2
Dec 30, 2024
TeamPass privileges issue
Critical
Network
Low
None
None
TeamPass before 3.1.3.1 does not properly prevent a user from acting with the privileges of a different user_id. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
3.0.10
3.1.0
3.1.1
Fixed in
3.1.3.1
References
Updated Dec 30, 2024 · Source: OSV.dev
CVE-2024-50701
GHSA-2697-96mv-3gfm
Dec 30, 2024
TeamPass does not properly check whether a folder is in a user's allowed folders list
Medium
Network
Low
Low
None
TeamPass before 3.1.3.1, when retrieving information about access rights for a folder, does not properly check whether a folder is in a user's allowed folders list that has been defined by an admin. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
3.0.10
3.1.0
3.1.1
Fixed in
3.1.3.1
References
Updated Dec 30, 2024 · Source: OSV.dev |
3.0.10
patch
Dependencies (33)
+ 25 more
Changelog
Compare changes
|
|
3.0.0.11
patch
22 CVEs
CVE-2024-50702
GHSA-7rm3-4w6j-8xx4
Dec 30, 2024
TeamPass mail_me operation authorization issue
Medium
Network
Low
Low
None
TeamPass before 3.1.3.1 does not properly check whether a mail_me (aka action_mail) operation is on behalf of an administrator or manager. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
3.0.10
3.1.0
3.1.1
Fixed in
3.1.3.1
References
Updated Dec 30, 2024 · Source: OSV.dev
CVE-2024-50703
GHSA-9wmc-988h-2mv2
Dec 30, 2024
TeamPass privileges issue
Critical
Network
Low
None
None
TeamPass before 3.1.3.1 does not properly prevent a user from acting with the privileges of a different user_id. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
3.0.10
3.1.0
3.1.1
Fixed in
3.1.3.1
References
Updated Dec 30, 2024 · Source: OSV.dev
CVE-2024-50701
GHSA-2697-96mv-3gfm
Dec 30, 2024
TeamPass does not properly check whether a folder is in a user's allowed folders list
Medium
Network
Low
Low
None
TeamPass before 3.1.3.1, when retrieving information about access rights for a folder, does not properly check whether a folder is in a user's allowed folders list that has been defined by an admin. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
3.0.10
3.1.0
3.1.1
Fixed in
3.1.3.1
References
Updated Dec 30, 2024 · Source: OSV.dev
CVE-2023-3565
GHSA-524r-w8fx-hqg3
Jul 10, 2023
TeamPass Cross-site Scripting vulnerability
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Cross-site Scripting (XSS) - Generic in GitHub repository nilsteampassnet/teampass prior to 3.0.10. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.10
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3553
GHSA-2rhg-hqq9-8xjh
Jul 08, 2023
TeamPass information exposure vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
TeamPass prior to 3.0.10 allows unauthenticated actors to view application-specific and user data and files by viewing an endpoint directory listing. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.10
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3552
GHSA-2cv5-qvq3-6276
Jul 08, 2023
TeamPass vulnerable to Improper Encoding or Escaping of Output
7.6
/ 10
High
Network
Low
Low
Required
Changed
High
Low
None
TeamPass prior to 3.0.10 is vulnerable to cross-site scripting filter bypass in folder names. This can lead to information disclosure. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.10
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3551
GHSA-97hm-2mfr-2p97
Jul 08, 2023
TeamPass Code Injection vulnerability
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Code Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.10. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.10
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3531
GHSA-pwrw-g29q-3mp8
Jul 06, 2023
TeamPass Cross-site Scripting vulnerability
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.10. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.10
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3191
GHSA-qmw8-x364-xxxm
Jun 10, 2023
Teampass Cross-site Scripting vulnerability
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In versions of nilsteampassnet/teampass prior to 3.0.9 some user input was not properly sanitized which may have lead to stored cross-site scripting (XSS) vectors in the application. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.9
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3190
GHSA-p7xm-g427-jxfc
Jun 10, 2023
Teampass Cross-site Scripting vulnerability
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
In versions of nilsteampassnet/teampass prior to 3.0.9 some user input was not properly sanitized which may have lead to stored cross-site scripting (XSS) vectors in the application. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.9
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3095
GHSA-g3jr-6vj4-3x82
Jun 04, 2023
TeamPass vulnerable to Improper Access Control
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Improper Access Control in GitHub repository nilsteampassnet/teampass prior to 3.0.9. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.9
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3086
GHSA-j245-v2mh-5h6f
Jun 03, 2023
TeamPass vulnerable to stored Cross-site Scripting
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.9
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3084
GHSA-8vm8-38pc-8xhh
Jun 03, 2023
TeamPass vulnerable to stored Cross-site Scripting
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.9
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3083
GHSA-c6fv-3jm9-6r8f
Jun 03, 2023
TeamPass vulnerable to stored Cross-site Scripting
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.9
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3009
GHSA-h5g9-2p35-54c7
May 31, 2023
nilsteampassnet/teampass vulnerable to cross-site scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. This enables an attacker to inject malicious code into a shared folder, which can then be executed by other users who have access to the folder. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.9
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-2859
GHSA-h6jh-cf83-qcq5
May 24, 2023
Code injection in nilsteampassnet/teampass
7.1
/ 10
High
Network
Low
None
Required
Unchanged
Low
High
None
nilsteampassnet/teampass prior to 3.0.9 is vulnerable to code injection. A malicious user could potentially rename a folder with a payload containing malicious code. This could result in an attack on an admin who edits the folder, as the payload could execute upon the admin's interaction with the folder. This attack could potentially allow the attacker to gain unauthorized access to the admin's system or steal sensitive information, or it could force admin to get redirected to a website controlled by the attacker. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.9
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-2591
GHSA-prj5-2g2p-x2mw
May 09, 2023
teampass vulnerable to code injection
7.1
/ 10
High
Network
Low
None
Required
Unchanged
Low
High
None
In nilsteampassnet/teampass prior to 3.0.7, if two users have the same folder access, malicious users can create an item where its label field is vulnerable to HTML injection. When other users see that item, it may force them to redirect to the attacker's website or capture their data using a form. The issue is fixed in version 3.0.7. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.7
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-2516
GHSA-2ffp-w665-9mgx
May 05, 2023
Cross Site Scripting in nilsteampassnet/teampass
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
nilsteampassnet/teampass prior to version 3.0.7 is vulnerable to cross site scripting (XSS) from item names within a folder. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.7
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-2021
GHSA-4h2q-84w7-4mhx
Apr 13, 2023
nilsteampassnet/teampass vulnerable to stored cross-site scripting (XSS)
5.8
/ 10
Medium
Local
High
None
Required
Unchanged
High
Low
Low
nilsteampassnet/teampass prior to 3.0.3 is vulnerable to stored cross-site scripting (XSS) in the description parameter of a folder. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.3
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-1545
GHSA-ppxm-q2h4-v7mm
Mar 21, 2023
Teampass SQL Injection vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SQL Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.0.22. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.0.22
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-1463
GHSA-86jq-pwgx-6vrq
Mar 17, 2023
Improper Authorization in nilsteampassnet/teampass
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
Improper Authorization in GitHub repository nilsteampassnet/teampass prior to 3.0.0.23. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.0.23
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-1070
GHSA-x36g-4629-xp9v
Feb 27, 2023
TeamPass External Control of File Name or Path vulnerability
7.1
/ 10
High
Network
Low
Low
None
Unchanged
None
Low
High
External Control of File Name or Path in GitHub repository nilsteampassnet/teampass prior to 3.0.0.22. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.0.23
References Updated Nov 08, 2023 · Source: OSV.dev | ||
3.0.0.10
patch
22 CVEs
CVE-2024-50702
GHSA-7rm3-4w6j-8xx4
Dec 30, 2024
TeamPass mail_me operation authorization issue
Medium
Network
Low
Low
None
TeamPass before 3.1.3.1 does not properly check whether a mail_me (aka action_mail) operation is on behalf of an administrator or manager. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
3.0.10
3.1.0
3.1.1
Fixed in
3.1.3.1
References
Updated Dec 30, 2024 · Source: OSV.dev
CVE-2024-50703
GHSA-9wmc-988h-2mv2
Dec 30, 2024
TeamPass privileges issue
Critical
Network
Low
None
None
TeamPass before 3.1.3.1 does not properly prevent a user from acting with the privileges of a different user_id. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
3.0.10
3.1.0
3.1.1
Fixed in
3.1.3.1
References
Updated Dec 30, 2024 · Source: OSV.dev
CVE-2024-50701
GHSA-2697-96mv-3gfm
Dec 30, 2024
TeamPass does not properly check whether a folder is in a user's allowed folders list
Medium
Network
Low
Low
None
TeamPass before 3.1.3.1, when retrieving information about access rights for a folder, does not properly check whether a folder is in a user's allowed folders list that has been defined by an admin. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
3.0.10
3.1.0
3.1.1
Fixed in
3.1.3.1
References
Updated Dec 30, 2024 · Source: OSV.dev
CVE-2023-3565
GHSA-524r-w8fx-hqg3
Jul 10, 2023
TeamPass Cross-site Scripting vulnerability
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Cross-site Scripting (XSS) - Generic in GitHub repository nilsteampassnet/teampass prior to 3.0.10. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.10
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3553
GHSA-2rhg-hqq9-8xjh
Jul 08, 2023
TeamPass information exposure vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
TeamPass prior to 3.0.10 allows unauthenticated actors to view application-specific and user data and files by viewing an endpoint directory listing. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.10
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3552
GHSA-2cv5-qvq3-6276
Jul 08, 2023
TeamPass vulnerable to Improper Encoding or Escaping of Output
7.6
/ 10
High
Network
Low
Low
Required
Changed
High
Low
None
TeamPass prior to 3.0.10 is vulnerable to cross-site scripting filter bypass in folder names. This can lead to information disclosure. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.10
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3551
GHSA-97hm-2mfr-2p97
Jul 08, 2023
TeamPass Code Injection vulnerability
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Code Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.10. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.10
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3531
GHSA-pwrw-g29q-3mp8
Jul 06, 2023
TeamPass Cross-site Scripting vulnerability
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.10. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.10
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3191
GHSA-qmw8-x364-xxxm
Jun 10, 2023
Teampass Cross-site Scripting vulnerability
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In versions of nilsteampassnet/teampass prior to 3.0.9 some user input was not properly sanitized which may have lead to stored cross-site scripting (XSS) vectors in the application. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.9
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3190
GHSA-p7xm-g427-jxfc
Jun 10, 2023
Teampass Cross-site Scripting vulnerability
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
In versions of nilsteampassnet/teampass prior to 3.0.9 some user input was not properly sanitized which may have lead to stored cross-site scripting (XSS) vectors in the application. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.9
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3095
GHSA-g3jr-6vj4-3x82
Jun 04, 2023
TeamPass vulnerable to Improper Access Control
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Improper Access Control in GitHub repository nilsteampassnet/teampass prior to 3.0.9. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.9
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3086
GHSA-j245-v2mh-5h6f
Jun 03, 2023
TeamPass vulnerable to stored Cross-site Scripting
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.9
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3084
GHSA-8vm8-38pc-8xhh
Jun 03, 2023
TeamPass vulnerable to stored Cross-site Scripting
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.9
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3083
GHSA-c6fv-3jm9-6r8f
Jun 03, 2023
TeamPass vulnerable to stored Cross-site Scripting
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.9
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3009
GHSA-h5g9-2p35-54c7
May 31, 2023
nilsteampassnet/teampass vulnerable to cross-site scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. This enables an attacker to inject malicious code into a shared folder, which can then be executed by other users who have access to the folder. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.9
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-2859
GHSA-h6jh-cf83-qcq5
May 24, 2023
Code injection in nilsteampassnet/teampass
7.1
/ 10
High
Network
Low
None
Required
Unchanged
Low
High
None
nilsteampassnet/teampass prior to 3.0.9 is vulnerable to code injection. A malicious user could potentially rename a folder with a payload containing malicious code. This could result in an attack on an admin who edits the folder, as the payload could execute upon the admin's interaction with the folder. This attack could potentially allow the attacker to gain unauthorized access to the admin's system or steal sensitive information, or it could force admin to get redirected to a website controlled by the attacker. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.9
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-2591
GHSA-prj5-2g2p-x2mw
May 09, 2023
teampass vulnerable to code injection
7.1
/ 10
High
Network
Low
None
Required
Unchanged
Low
High
None
In nilsteampassnet/teampass prior to 3.0.7, if two users have the same folder access, malicious users can create an item where its label field is vulnerable to HTML injection. When other users see that item, it may force them to redirect to the attacker's website or capture their data using a form. The issue is fixed in version 3.0.7. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.7
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-2516
GHSA-2ffp-w665-9mgx
May 05, 2023
Cross Site Scripting in nilsteampassnet/teampass
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
nilsteampassnet/teampass prior to version 3.0.7 is vulnerable to cross site scripting (XSS) from item names within a folder. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.7
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-2021
GHSA-4h2q-84w7-4mhx
Apr 13, 2023
nilsteampassnet/teampass vulnerable to stored cross-site scripting (XSS)
5.8
/ 10
Medium
Local
High
None
Required
Unchanged
High
Low
Low
nilsteampassnet/teampass prior to 3.0.3 is vulnerable to stored cross-site scripting (XSS) in the description parameter of a folder. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.3
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-1545
GHSA-ppxm-q2h4-v7mm
Mar 21, 2023
Teampass SQL Injection vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SQL Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.0.22. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.0.22
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-1463
GHSA-86jq-pwgx-6vrq
Mar 17, 2023
Improper Authorization in nilsteampassnet/teampass
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
Improper Authorization in GitHub repository nilsteampassnet/teampass prior to 3.0.0.23. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.0.23
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-1070
GHSA-x36g-4629-xp9v
Feb 27, 2023
TeamPass External Control of File Name or Path vulnerability
7.1
/ 10
High
Network
Low
Low
None
Unchanged
None
Low
High
External Control of File Name or Path in GitHub repository nilsteampassnet/teampass prior to 3.0.0.22. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.0.23
References Updated Nov 08, 2023 · Source: OSV.dev | ||
3.0.0
major
22 CVEs
CVE-2024-50702
GHSA-7rm3-4w6j-8xx4
Dec 30, 2024
TeamPass mail_me operation authorization issue
Medium
Network
Low
Low
None
TeamPass before 3.1.3.1 does not properly check whether a mail_me (aka action_mail) operation is on behalf of an administrator or manager. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
3.0.10
3.1.0
3.1.1
Fixed in
3.1.3.1
References
Updated Dec 30, 2024 · Source: OSV.dev
CVE-2024-50703
GHSA-9wmc-988h-2mv2
Dec 30, 2024
TeamPass privileges issue
Critical
Network
Low
None
None
TeamPass before 3.1.3.1 does not properly prevent a user from acting with the privileges of a different user_id. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
3.0.10
3.1.0
3.1.1
Fixed in
3.1.3.1
References
Updated Dec 30, 2024 · Source: OSV.dev
CVE-2024-50701
GHSA-2697-96mv-3gfm
Dec 30, 2024
TeamPass does not properly check whether a folder is in a user's allowed folders list
Medium
Network
Low
Low
None
TeamPass before 3.1.3.1, when retrieving information about access rights for a folder, does not properly check whether a folder is in a user's allowed folders list that has been defined by an admin. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
3.0.10
3.1.0
3.1.1
Fixed in
3.1.3.1
References
Updated Dec 30, 2024 · Source: OSV.dev
CVE-2023-3565
GHSA-524r-w8fx-hqg3
Jul 10, 2023
TeamPass Cross-site Scripting vulnerability
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Cross-site Scripting (XSS) - Generic in GitHub repository nilsteampassnet/teampass prior to 3.0.10. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.10
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3553
GHSA-2rhg-hqq9-8xjh
Jul 08, 2023
TeamPass information exposure vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
TeamPass prior to 3.0.10 allows unauthenticated actors to view application-specific and user data and files by viewing an endpoint directory listing. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.10
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3552
GHSA-2cv5-qvq3-6276
Jul 08, 2023
TeamPass vulnerable to Improper Encoding or Escaping of Output
7.6
/ 10
High
Network
Low
Low
Required
Changed
High
Low
None
TeamPass prior to 3.0.10 is vulnerable to cross-site scripting filter bypass in folder names. This can lead to information disclosure. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.10
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3551
GHSA-97hm-2mfr-2p97
Jul 08, 2023
TeamPass Code Injection vulnerability
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Code Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.10. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.10
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3531
GHSA-pwrw-g29q-3mp8
Jul 06, 2023
TeamPass Cross-site Scripting vulnerability
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.10. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.10
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3191
GHSA-qmw8-x364-xxxm
Jun 10, 2023
Teampass Cross-site Scripting vulnerability
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In versions of nilsteampassnet/teampass prior to 3.0.9 some user input was not properly sanitized which may have lead to stored cross-site scripting (XSS) vectors in the application. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.9
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3190
GHSA-p7xm-g427-jxfc
Jun 10, 2023
Teampass Cross-site Scripting vulnerability
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
In versions of nilsteampassnet/teampass prior to 3.0.9 some user input was not properly sanitized which may have lead to stored cross-site scripting (XSS) vectors in the application. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.9
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3095
GHSA-g3jr-6vj4-3x82
Jun 04, 2023
TeamPass vulnerable to Improper Access Control
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Improper Access Control in GitHub repository nilsteampassnet/teampass prior to 3.0.9. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.9
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3086
GHSA-j245-v2mh-5h6f
Jun 03, 2023
TeamPass vulnerable to stored Cross-site Scripting
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.9
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3084
GHSA-8vm8-38pc-8xhh
Jun 03, 2023
TeamPass vulnerable to stored Cross-site Scripting
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.9
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3083
GHSA-c6fv-3jm9-6r8f
Jun 03, 2023
TeamPass vulnerable to stored Cross-site Scripting
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.9
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3009
GHSA-h5g9-2p35-54c7
May 31, 2023
nilsteampassnet/teampass vulnerable to cross-site scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. This enables an attacker to inject malicious code into a shared folder, which can then be executed by other users who have access to the folder. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.9
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-2859
GHSA-h6jh-cf83-qcq5
May 24, 2023
Code injection in nilsteampassnet/teampass
7.1
/ 10
High
Network
Low
None
Required
Unchanged
Low
High
None
nilsteampassnet/teampass prior to 3.0.9 is vulnerable to code injection. A malicious user could potentially rename a folder with a payload containing malicious code. This could result in an attack on an admin who edits the folder, as the payload could execute upon the admin's interaction with the folder. This attack could potentially allow the attacker to gain unauthorized access to the admin's system or steal sensitive information, or it could force admin to get redirected to a website controlled by the attacker. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.9
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-2591
GHSA-prj5-2g2p-x2mw
May 09, 2023
teampass vulnerable to code injection
7.1
/ 10
High
Network
Low
None
Required
Unchanged
Low
High
None
In nilsteampassnet/teampass prior to 3.0.7, if two users have the same folder access, malicious users can create an item where its label field is vulnerable to HTML injection. When other users see that item, it may force them to redirect to the attacker's website or capture their data using a form. The issue is fixed in version 3.0.7. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.7
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-2516
GHSA-2ffp-w665-9mgx
May 05, 2023
Cross Site Scripting in nilsteampassnet/teampass
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
nilsteampassnet/teampass prior to version 3.0.7 is vulnerable to cross site scripting (XSS) from item names within a folder. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.7
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-2021
GHSA-4h2q-84w7-4mhx
Apr 13, 2023
nilsteampassnet/teampass vulnerable to stored cross-site scripting (XSS)
5.8
/ 10
Medium
Local
High
None
Required
Unchanged
High
Low
Low
nilsteampassnet/teampass prior to 3.0.3 is vulnerable to stored cross-site scripting (XSS) in the description parameter of a folder. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.3
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-1545
GHSA-ppxm-q2h4-v7mm
Mar 21, 2023
Teampass SQL Injection vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SQL Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.0.22. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.0.22
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-1463
GHSA-86jq-pwgx-6vrq
Mar 17, 2023
Improper Authorization in nilsteampassnet/teampass
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
Improper Authorization in GitHub repository nilsteampassnet/teampass prior to 3.0.0.23. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.0.23
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-1070
GHSA-x36g-4629-xp9v
Feb 27, 2023
TeamPass External Control of File Name or Path vulnerability
7.1
/ 10
High
Network
Low
Low
None
Unchanged
None
Low
High
External Control of File Name or Path in GitHub repository nilsteampassnet/teampass prior to 3.0.0.22. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.0.23
References Updated Nov 08, 2023 · Source: OSV.dev | ||
2.1.27
patch
38 CVEs
CVE-2024-50702
GHSA-7rm3-4w6j-8xx4
Dec 30, 2024
TeamPass mail_me operation authorization issue
Medium
Network
Low
Low
None
TeamPass before 3.1.3.1 does not properly check whether a mail_me (aka action_mail) operation is on behalf of an administrator or manager. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
3.0.10
3.1.0
3.1.1
Fixed in
3.1.3.1
References
Updated Dec 30, 2024 · Source: OSV.dev
CVE-2024-50703
GHSA-9wmc-988h-2mv2
Dec 30, 2024
TeamPass privileges issue
Critical
Network
Low
None
None
TeamPass before 3.1.3.1 does not properly prevent a user from acting with the privileges of a different user_id. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
3.0.10
3.1.0
3.1.1
Fixed in
3.1.3.1
References
Updated Dec 30, 2024 · Source: OSV.dev
CVE-2024-50701
GHSA-2697-96mv-3gfm
Dec 30, 2024
TeamPass does not properly check whether a folder is in a user's allowed folders list
Medium
Network
Low
Low
None
TeamPass before 3.1.3.1, when retrieving information about access rights for a folder, does not properly check whether a folder is in a user's allowed folders list that has been defined by an admin. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
3.0.10
3.1.0
3.1.1
Fixed in
3.1.3.1
References
Updated Dec 30, 2024 · Source: OSV.dev
CVE-2023-3565
GHSA-524r-w8fx-hqg3
Jul 10, 2023
TeamPass Cross-site Scripting vulnerability
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Cross-site Scripting (XSS) - Generic in GitHub repository nilsteampassnet/teampass prior to 3.0.10. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.10
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3553
GHSA-2rhg-hqq9-8xjh
Jul 08, 2023
TeamPass information exposure vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
TeamPass prior to 3.0.10 allows unauthenticated actors to view application-specific and user data and files by viewing an endpoint directory listing. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.10
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3552
GHSA-2cv5-qvq3-6276
Jul 08, 2023
TeamPass vulnerable to Improper Encoding or Escaping of Output
7.6
/ 10
High
Network
Low
Low
Required
Changed
High
Low
None
TeamPass prior to 3.0.10 is vulnerable to cross-site scripting filter bypass in folder names. This can lead to information disclosure. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.10
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3551
GHSA-97hm-2mfr-2p97
Jul 08, 2023
TeamPass Code Injection vulnerability
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Code Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.10. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.10
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3531
GHSA-pwrw-g29q-3mp8
Jul 06, 2023
TeamPass Cross-site Scripting vulnerability
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.10. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.10
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3191
GHSA-qmw8-x364-xxxm
Jun 10, 2023
Teampass Cross-site Scripting vulnerability
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In versions of nilsteampassnet/teampass prior to 3.0.9 some user input was not properly sanitized which may have lead to stored cross-site scripting (XSS) vectors in the application. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.9
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3190
GHSA-p7xm-g427-jxfc
Jun 10, 2023
Teampass Cross-site Scripting vulnerability
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
In versions of nilsteampassnet/teampass prior to 3.0.9 some user input was not properly sanitized which may have lead to stored cross-site scripting (XSS) vectors in the application. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.9
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3095
GHSA-g3jr-6vj4-3x82
Jun 04, 2023
TeamPass vulnerable to Improper Access Control
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Improper Access Control in GitHub repository nilsteampassnet/teampass prior to 3.0.9. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.9
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3086
GHSA-j245-v2mh-5h6f
Jun 03, 2023
TeamPass vulnerable to stored Cross-site Scripting
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.9
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3084
GHSA-8vm8-38pc-8xhh
Jun 03, 2023
TeamPass vulnerable to stored Cross-site Scripting
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.9
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3083
GHSA-c6fv-3jm9-6r8f
Jun 03, 2023
TeamPass vulnerable to stored Cross-site Scripting
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.9
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3009
GHSA-h5g9-2p35-54c7
May 31, 2023
nilsteampassnet/teampass vulnerable to cross-site scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. This enables an attacker to inject malicious code into a shared folder, which can then be executed by other users who have access to the folder. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.9
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-2859
GHSA-h6jh-cf83-qcq5
May 24, 2023
Code injection in nilsteampassnet/teampass
7.1
/ 10
High
Network
Low
None
Required
Unchanged
Low
High
None
nilsteampassnet/teampass prior to 3.0.9 is vulnerable to code injection. A malicious user could potentially rename a folder with a payload containing malicious code. This could result in an attack on an admin who edits the folder, as the payload could execute upon the admin's interaction with the folder. This attack could potentially allow the attacker to gain unauthorized access to the admin's system or steal sensitive information, or it could force admin to get redirected to a website controlled by the attacker. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.9
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-2591
GHSA-prj5-2g2p-x2mw
May 09, 2023
teampass vulnerable to code injection
7.1
/ 10
High
Network
Low
None
Required
Unchanged
Low
High
None
In nilsteampassnet/teampass prior to 3.0.7, if two users have the same folder access, malicious users can create an item where its label field is vulnerable to HTML injection. When other users see that item, it may force them to redirect to the attacker's website or capture their data using a form. The issue is fixed in version 3.0.7. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.7
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-2516
GHSA-2ffp-w665-9mgx
May 05, 2023
Cross Site Scripting in nilsteampassnet/teampass
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
nilsteampassnet/teampass prior to version 3.0.7 is vulnerable to cross site scripting (XSS) from item names within a folder. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.7
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-2021
GHSA-4h2q-84w7-4mhx
Apr 13, 2023
nilsteampassnet/teampass vulnerable to stored cross-site scripting (XSS)
5.8
/ 10
Medium
Local
High
None
Required
Unchanged
High
Low
Low
nilsteampassnet/teampass prior to 3.0.3 is vulnerable to stored cross-site scripting (XSS) in the description parameter of a folder. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.3
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-1545
GHSA-ppxm-q2h4-v7mm
Mar 21, 2023
Teampass SQL Injection vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SQL Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.0.22. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.0.22
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-1463
GHSA-86jq-pwgx-6vrq
Mar 17, 2023
Improper Authorization in nilsteampassnet/teampass
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
Improper Authorization in GitHub repository nilsteampassnet/teampass prior to 3.0.0.23. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.0.23
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-1070
GHSA-x36g-4629-xp9v
Feb 27, 2023
TeamPass External Control of File Name or Path vulnerability
7.1
/ 10
High
Network
Low
Low
None
Unchanged
None
Low
High
External Control of File Name or Path in GitHub repository nilsteampassnet/teampass prior to 3.0.0.22. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.0.23
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2019-16904
GHSA-rpmr-fwh5-24fm
May 24, 2022
TeamPass Cross-site Scripting (XSS) vulnerability
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
TeamPass 2.1.27.36 allows XSS by setting a crafted password for an item in a folder, and then sharing that item with an admin. (The crafted password is exploitable when viewing the change history, or the previous used password field.) Affected versions
2.1.21
2.1.26
2.1.27
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2020-12479
GHSA-6jf9-8m34-96w5
May 24, 2022
TeamPass PHP arbitrary file include vulnerability
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
TeamPass 2.1.27.36 allows any authenticated TeamPass user to trigger a PHP file include vulnerability via a crafted HTTP request with sources/users.queries.php newValue directory traversal. Affected versions
2.1.21
2.1.26
2.1.27
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2019-17205
GHSA-v969-5v7f-pmg2
May 24, 2022
TeamPass Stored Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
TeamPass 2.1.27.36 allows Stored XSS by placing a payload in the username field during a login attempt. When an administrator looks at the log of failed logins, the XSS payload will be executed. Affected versions
2.1.21
2.1.26
2.1.27
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2019-17204
GHSA-qx37-225j-qr89
May 24, 2022
TeamPass Stored Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
TeamPass 2.1.27.36 allows Stored XSS by setting a crafted Knowledge Base label and adding any available item. Affected versions
2.1.21
2.1.26
2.1.27
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2019-17203
GHSA-pqx8-q35p-pgcv
May 24, 2022
TeamPass Stored Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
TeamPass 2.1.27.36 allows Stored XSS at the Search page by setting a crafted password for an item in any folder. Affected versions
2.1.21
2.1.26
2.1.27
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2019-12950
GHSA-m3pp-jcpm-2vr9
May 24, 2022
TeamPass Cross-site Scripting (XSS)
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
An issue was discovered in TeamPass 2.1.27.35. From the sources/items.queries.php "Import items" feature, it is possible to load a crafted CSV file with an XSS payload. Affected versions
2.1.21
2.1.26
2.1.27
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2017-9436
GHSA-cm26-gp8j-w6xf
May 17, 2022
TeamPass SQL injection in users.queries.php
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
TeamPass before 2.1.27.5 is vulnerable to a SQL injection in users.queries.php. Affected versions
2.1.21
2.1.26
2.1.27
Fixed in
2.1.27.5
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2017-15278
GHSA-28pv-2j2h-fmhc
May 17, 2022
TeamPass Cross-Site Scripting (XSS)
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Cross-Site Scripting (XSS) was discovered in TeamPass before 2.1.27.9. The vulnerability exists due to insufficient filtration of data (in /sources/folders.queries.php). An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website. Affected versions
2.1.21
2.1.26
2.1.27
Fixed in
2.1.27.9
References
Updated Apr 24, 2024 · Source: OSV.dev
CVE-2017-15051
GHSA-r68m-4v39-cf43
May 17, 2022
TeamPass stored cross-site scripting (XSS) vulnerability
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Multiple stored cross-site scripting (XSS) vulnerabilities in TeamPass before 2.1.27.9 allow authenticated remote attackers to inject arbitrary web script or HTML via the (1) URL value of an item or (2) user log history. To exploit the vulnerability, the attacker must be first authenticated to the application. For the first one, the attacker has to simply inject XSS code within the URL field of a shared item. For the second one however, the attacker must prepare a payload within its profile, and then ask an administrator to modify its profile. From there, whenever the administrator accesses the log, it can be XSS'ed. Affected versions
2.1.21
2.1.26
2.1.27
Fixed in
2.1.27.9
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2017-15054
GHSA-rm3q-qfrm-frrv
May 17, 2022
TeamPass arbitrary file upload vulnerability
7.5
/ 10
High
Network
High
Low
None
Unchanged
High
High
High
An arbitrary file upload vulnerability, present in TeamPass before 2.1.27.9, allows remote authenticated users to upload arbitrary files leading to Remote Command Execution. To exploit this vulnerability, an authenticated attacker has to tamper with parameters of a request to upload.files.php, in order to select the correct branch and be able to upload any arbitrary file. From there, it can simply access the file to execute code on the server. Affected versions
2.1.21
2.1.26
2.1.27
Fixed in
2.1.27.9
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2017-15055
GHSA-7ghm-6p42-h226
May 13, 2022
TeamPass Improper Privilege Management
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
TeamPass before 2.1.27.9 does not properly enforce item access control when requesting items.queries.php. It is then possible to copy any arbitrary item into a directory controlled by the attacker, edit any item within a read-only directory, delete an arbitrary item, delete the file attachments of an arbitrary item, copy the password of an arbitrary item to the copy/paste buffer, access the history of an arbitrary item, and edit attributes of an arbitrary directory. To exploit the vulnerability, an authenticated attacker must tamper with the requests sent directly, for example by changing the "item_id" parameter when invoking "copy_item" on items.queries.php. Affected versions
2.1.21
2.1.26
2.1.27
Fixed in
2.1.27.9
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2017-15052
GHSA-5qr3-4839-88gf
May 13, 2022
TeamPass Improper Privilege Management
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
None
TeamPass before 2.1.27.9 does not properly enforce manager access control when requesting users.queries.php. It is then possible for a manager user to delete an arbitrary user (including admin), or modify attributes of any arbitrary user except administrator. To exploit the vulnerability, an authenticated attacker must have the manager rights on the application, then tamper with the requests sent directly, for example by changing the "id" parameter when invoking "delete_user" on users.queries.php. Affected versions
2.1.21
2.1.26
2.1.27
Fixed in
2.1.27.9
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2017-15053
GHSA-xvjf-394g-phrr
May 13, 2022
TeamPass Improper Privilege Management
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
None
TeamPass before 2.1.27.9 does not properly enforce manager access control when requesting roles.queries.php. It is then possible for a manager user to modify any arbitrary roles within the application, or delete any arbitrary role. To exploit the vulnerability, an authenticated attacker must have the manager rights on the application, then tamper with the requests sent directly, for example by changing the "id" parameter when invoking "delete_role" on roles.queries.php. Affected versions
2.1.21
2.1.26
2.1.27
Fixed in
2.1.27.9
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2019-1000001
GHSA-q9qr-h33g-fw3j
May 13, 2022
TeamPass Storing Passwords in a Recoverable Format vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
TeamPass version 2.1.27 and earlier contains a Storing Passwords in a Recoverable Format vulnerability in Shared password vaults that can result in all shared passwords are recoverable server side. This attack appears to be exploitable via any vulnerability that can bypass authentication or role assignment and can lead to shared password leakage. Affected versions
2.1.21
2.1.26
2.1.27
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2020-11671
GHSA-gmr7-m73x-6c9q
Jul 26, 2021
Missing Authorization in TeamPass
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Lack of authorization controls in REST API functions in TeamPass through 2.1.27.36 allows any TeamPass user with a valid API token to become a TeamPass administrator and read/modify all passwords via authenticated api/index.php REST API calls. NOTE: the API is not available by default. Affected versions
2.1.21
2.1.26
2.1.27
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-12477
GHSA-fv48-hjhp-94c7
Jul 26, 2021
Incorrect Authorization in TeamPass
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
The REST API functions in TeamPass 2.1.27.36 allow any user with a valid API token to bypass IP address whitelist restrictions via an X-Forwarded-For client HTTP header to the getIp function. Affected versions
2.1.21
2.1.26
2.1.27
References Updated Nov 08, 2023 · Source: OSV.dev | ||
2.1.26
patch
39 CVEs
CVE-2024-50702
GHSA-7rm3-4w6j-8xx4
Dec 30, 2024
TeamPass mail_me operation authorization issue
Medium
Network
Low
Low
None
TeamPass before 3.1.3.1 does not properly check whether a mail_me (aka action_mail) operation is on behalf of an administrator or manager. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
3.0.10
3.1.0
3.1.1
Fixed in
3.1.3.1
References
Updated Dec 30, 2024 · Source: OSV.dev
CVE-2024-50703
GHSA-9wmc-988h-2mv2
Dec 30, 2024
TeamPass privileges issue
Critical
Network
Low
None
None
TeamPass before 3.1.3.1 does not properly prevent a user from acting with the privileges of a different user_id. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
3.0.10
3.1.0
3.1.1
Fixed in
3.1.3.1
References
Updated Dec 30, 2024 · Source: OSV.dev
CVE-2024-50701
GHSA-2697-96mv-3gfm
Dec 30, 2024
TeamPass does not properly check whether a folder is in a user's allowed folders list
Medium
Network
Low
Low
None
TeamPass before 3.1.3.1, when retrieving information about access rights for a folder, does not properly check whether a folder is in a user's allowed folders list that has been defined by an admin. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
3.0.10
3.1.0
3.1.1
Fixed in
3.1.3.1
References
Updated Dec 30, 2024 · Source: OSV.dev
CVE-2023-3565
GHSA-524r-w8fx-hqg3
Jul 10, 2023
TeamPass Cross-site Scripting vulnerability
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Cross-site Scripting (XSS) - Generic in GitHub repository nilsteampassnet/teampass prior to 3.0.10. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.10
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3553
GHSA-2rhg-hqq9-8xjh
Jul 08, 2023
TeamPass information exposure vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
TeamPass prior to 3.0.10 allows unauthenticated actors to view application-specific and user data and files by viewing an endpoint directory listing. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.10
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3552
GHSA-2cv5-qvq3-6276
Jul 08, 2023
TeamPass vulnerable to Improper Encoding or Escaping of Output
7.6
/ 10
High
Network
Low
Low
Required
Changed
High
Low
None
TeamPass prior to 3.0.10 is vulnerable to cross-site scripting filter bypass in folder names. This can lead to information disclosure. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.10
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3551
GHSA-97hm-2mfr-2p97
Jul 08, 2023
TeamPass Code Injection vulnerability
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Code Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.10. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.10
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3531
GHSA-pwrw-g29q-3mp8
Jul 06, 2023
TeamPass Cross-site Scripting vulnerability
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.10. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.10
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3191
GHSA-qmw8-x364-xxxm
Jun 10, 2023
Teampass Cross-site Scripting vulnerability
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In versions of nilsteampassnet/teampass prior to 3.0.9 some user input was not properly sanitized which may have lead to stored cross-site scripting (XSS) vectors in the application. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.9
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3190
GHSA-p7xm-g427-jxfc
Jun 10, 2023
Teampass Cross-site Scripting vulnerability
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
In versions of nilsteampassnet/teampass prior to 3.0.9 some user input was not properly sanitized which may have lead to stored cross-site scripting (XSS) vectors in the application. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.9
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3095
GHSA-g3jr-6vj4-3x82
Jun 04, 2023
TeamPass vulnerable to Improper Access Control
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Improper Access Control in GitHub repository nilsteampassnet/teampass prior to 3.0.9. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.9
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3086
GHSA-j245-v2mh-5h6f
Jun 03, 2023
TeamPass vulnerable to stored Cross-site Scripting
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.9
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3084
GHSA-8vm8-38pc-8xhh
Jun 03, 2023
TeamPass vulnerable to stored Cross-site Scripting
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.9
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3083
GHSA-c6fv-3jm9-6r8f
Jun 03, 2023
TeamPass vulnerable to stored Cross-site Scripting
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.9
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3009
GHSA-h5g9-2p35-54c7
May 31, 2023
nilsteampassnet/teampass vulnerable to cross-site scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. This enables an attacker to inject malicious code into a shared folder, which can then be executed by other users who have access to the folder. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.9
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-2859
GHSA-h6jh-cf83-qcq5
May 24, 2023
Code injection in nilsteampassnet/teampass
7.1
/ 10
High
Network
Low
None
Required
Unchanged
Low
High
None
nilsteampassnet/teampass prior to 3.0.9 is vulnerable to code injection. A malicious user could potentially rename a folder with a payload containing malicious code. This could result in an attack on an admin who edits the folder, as the payload could execute upon the admin's interaction with the folder. This attack could potentially allow the attacker to gain unauthorized access to the admin's system or steal sensitive information, or it could force admin to get redirected to a website controlled by the attacker. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.9
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-2591
GHSA-prj5-2g2p-x2mw
May 09, 2023
teampass vulnerable to code injection
7.1
/ 10
High
Network
Low
None
Required
Unchanged
Low
High
None
In nilsteampassnet/teampass prior to 3.0.7, if two users have the same folder access, malicious users can create an item where its label field is vulnerable to HTML injection. When other users see that item, it may force them to redirect to the attacker's website or capture their data using a form. The issue is fixed in version 3.0.7. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.7
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-2516
GHSA-2ffp-w665-9mgx
May 05, 2023
Cross Site Scripting in nilsteampassnet/teampass
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
nilsteampassnet/teampass prior to version 3.0.7 is vulnerable to cross site scripting (XSS) from item names within a folder. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.7
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-2021
GHSA-4h2q-84w7-4mhx
Apr 13, 2023
nilsteampassnet/teampass vulnerable to stored cross-site scripting (XSS)
5.8
/ 10
Medium
Local
High
None
Required
Unchanged
High
Low
Low
nilsteampassnet/teampass prior to 3.0.3 is vulnerable to stored cross-site scripting (XSS) in the description parameter of a folder. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.3
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-1545
GHSA-ppxm-q2h4-v7mm
Mar 21, 2023
Teampass SQL Injection vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SQL Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.0.22. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.0.22
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-1463
GHSA-86jq-pwgx-6vrq
Mar 17, 2023
Improper Authorization in nilsteampassnet/teampass
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
Improper Authorization in GitHub repository nilsteampassnet/teampass prior to 3.0.0.23. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.0.23
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-1070
GHSA-x36g-4629-xp9v
Feb 27, 2023
TeamPass External Control of File Name or Path vulnerability
7.1
/ 10
High
Network
Low
Low
None
Unchanged
None
Low
High
External Control of File Name or Path in GitHub repository nilsteampassnet/teampass prior to 3.0.0.22. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.0.23
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2019-16904
GHSA-rpmr-fwh5-24fm
May 24, 2022
TeamPass Cross-site Scripting (XSS) vulnerability
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
TeamPass 2.1.27.36 allows XSS by setting a crafted password for an item in a folder, and then sharing that item with an admin. (The crafted password is exploitable when viewing the change history, or the previous used password field.) Affected versions
2.1.21
2.1.26
2.1.27
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2020-12479
GHSA-6jf9-8m34-96w5
May 24, 2022
TeamPass PHP arbitrary file include vulnerability
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
TeamPass 2.1.27.36 allows any authenticated TeamPass user to trigger a PHP file include vulnerability via a crafted HTTP request with sources/users.queries.php newValue directory traversal. Affected versions
2.1.21
2.1.26
2.1.27
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2019-17205
GHSA-v969-5v7f-pmg2
May 24, 2022
TeamPass Stored Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
TeamPass 2.1.27.36 allows Stored XSS by placing a payload in the username field during a login attempt. When an administrator looks at the log of failed logins, the XSS payload will be executed. Affected versions
2.1.21
2.1.26
2.1.27
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2019-17204
GHSA-qx37-225j-qr89
May 24, 2022
TeamPass Stored Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
TeamPass 2.1.27.36 allows Stored XSS by setting a crafted Knowledge Base label and adding any available item. Affected versions
2.1.21
2.1.26
2.1.27
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2019-17203
GHSA-pqx8-q35p-pgcv
May 24, 2022
TeamPass Stored Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
TeamPass 2.1.27.36 allows Stored XSS at the Search page by setting a crafted password for an item in any folder. Affected versions
2.1.21
2.1.26
2.1.27
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2019-12950
GHSA-m3pp-jcpm-2vr9
May 24, 2022
TeamPass Cross-site Scripting (XSS)
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
An issue was discovered in TeamPass 2.1.27.35. From the sources/items.queries.php "Import items" feature, it is possible to load a crafted CSV file with an XSS payload. Affected versions
2.1.21
2.1.26
2.1.27
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2017-9436
GHSA-cm26-gp8j-w6xf
May 17, 2022
TeamPass SQL injection in users.queries.php
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
TeamPass before 2.1.27.5 is vulnerable to a SQL injection in users.queries.php. Affected versions
2.1.21
2.1.26
2.1.27
Fixed in
2.1.27.5
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2017-15278
GHSA-28pv-2j2h-fmhc
May 17, 2022
TeamPass Cross-Site Scripting (XSS)
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Cross-Site Scripting (XSS) was discovered in TeamPass before 2.1.27.9. The vulnerability exists due to insufficient filtration of data (in /sources/folders.queries.php). An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website. Affected versions
2.1.21
2.1.26
2.1.27
Fixed in
2.1.27.9
References
Updated Apr 24, 2024 · Source: OSV.dev
CVE-2017-15051
GHSA-r68m-4v39-cf43
May 17, 2022
TeamPass stored cross-site scripting (XSS) vulnerability
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Multiple stored cross-site scripting (XSS) vulnerabilities in TeamPass before 2.1.27.9 allow authenticated remote attackers to inject arbitrary web script or HTML via the (1) URL value of an item or (2) user log history. To exploit the vulnerability, the attacker must be first authenticated to the application. For the first one, the attacker has to simply inject XSS code within the URL field of a shared item. For the second one however, the attacker must prepare a payload within its profile, and then ask an administrator to modify its profile. From there, whenever the administrator accesses the log, it can be XSS'ed. Affected versions
2.1.21
2.1.26
2.1.27
Fixed in
2.1.27.9
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2017-15054
GHSA-rm3q-qfrm-frrv
May 17, 2022
TeamPass arbitrary file upload vulnerability
7.5
/ 10
High
Network
High
Low
None
Unchanged
High
High
High
An arbitrary file upload vulnerability, present in TeamPass before 2.1.27.9, allows remote authenticated users to upload arbitrary files leading to Remote Command Execution. To exploit this vulnerability, an authenticated attacker has to tamper with parameters of a request to upload.files.php, in order to select the correct branch and be able to upload any arbitrary file. From there, it can simply access the file to execute code on the server. Affected versions
2.1.21
2.1.26
2.1.27
Fixed in
2.1.27.9
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2017-15055
GHSA-7ghm-6p42-h226
May 13, 2022
TeamPass Improper Privilege Management
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
TeamPass before 2.1.27.9 does not properly enforce item access control when requesting items.queries.php. It is then possible to copy any arbitrary item into a directory controlled by the attacker, edit any item within a read-only directory, delete an arbitrary item, delete the file attachments of an arbitrary item, copy the password of an arbitrary item to the copy/paste buffer, access the history of an arbitrary item, and edit attributes of an arbitrary directory. To exploit the vulnerability, an authenticated attacker must tamper with the requests sent directly, for example by changing the "item_id" parameter when invoking "copy_item" on items.queries.php. Affected versions
2.1.21
2.1.26
2.1.27
Fixed in
2.1.27.9
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2017-15052
GHSA-5qr3-4839-88gf
May 13, 2022
TeamPass Improper Privilege Management
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
None
TeamPass before 2.1.27.9 does not properly enforce manager access control when requesting users.queries.php. It is then possible for a manager user to delete an arbitrary user (including admin), or modify attributes of any arbitrary user except administrator. To exploit the vulnerability, an authenticated attacker must have the manager rights on the application, then tamper with the requests sent directly, for example by changing the "id" parameter when invoking "delete_user" on users.queries.php. Affected versions
2.1.21
2.1.26
2.1.27
Fixed in
2.1.27.9
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2017-15053
GHSA-xvjf-394g-phrr
May 13, 2022
TeamPass Improper Privilege Management
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
None
TeamPass before 2.1.27.9 does not properly enforce manager access control when requesting roles.queries.php. It is then possible for a manager user to modify any arbitrary roles within the application, or delete any arbitrary role. To exploit the vulnerability, an authenticated attacker must have the manager rights on the application, then tamper with the requests sent directly, for example by changing the "id" parameter when invoking "delete_role" on roles.queries.php. Affected versions
2.1.21
2.1.26
2.1.27
Fixed in
2.1.27.9
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2019-1000001
GHSA-q9qr-h33g-fw3j
May 13, 2022
TeamPass Storing Passwords in a Recoverable Format vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
TeamPass version 2.1.27 and earlier contains a Storing Passwords in a Recoverable Format vulnerability in Shared password vaults that can result in all shared passwords are recoverable server side. This attack appears to be exploitable via any vulnerability that can bypass authentication or role assignment and can lead to shared password leakage. Affected versions
2.1.21
2.1.26
2.1.27
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2022-26980
GHSA-m2wv-m5pf-284r
Mar 29, 2022
Cross-site Scripting in teampass
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Teampass 2.1.26 allows reflected XSS via the index.php PATH_INFO. Someone must open a link for the Teampass Password Manager index page containing malicious payload. Affected versions
2.1.21
2.1.26
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-11671
GHSA-gmr7-m73x-6c9q
Jul 26, 2021
Missing Authorization in TeamPass
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Lack of authorization controls in REST API functions in TeamPass through 2.1.27.36 allows any TeamPass user with a valid API token to become a TeamPass administrator and read/modify all passwords via authenticated api/index.php REST API calls. NOTE: the API is not available by default. Affected versions
2.1.21
2.1.26
2.1.27
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-12477
GHSA-fv48-hjhp-94c7
Jul 26, 2021
Incorrect Authorization in TeamPass
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
The REST API functions in TeamPass 2.1.27.36 allow any user with a valid API token to bypass IP address whitelist restrictions via an X-Forwarded-For client HTTP header to the getIp function. Affected versions
2.1.21
2.1.26
2.1.27
References Updated Nov 08, 2023 · Source: OSV.dev | ||
2.1.21
initial
41 CVEs
CVE-2024-50702
GHSA-7rm3-4w6j-8xx4
Dec 30, 2024
TeamPass mail_me operation authorization issue
Medium
Network
Low
Low
None
TeamPass before 3.1.3.1 does not properly check whether a mail_me (aka action_mail) operation is on behalf of an administrator or manager. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
3.0.10
3.1.0
3.1.1
Fixed in
3.1.3.1
References
Updated Dec 30, 2024 · Source: OSV.dev
CVE-2024-50703
GHSA-9wmc-988h-2mv2
Dec 30, 2024
TeamPass privileges issue
Critical
Network
Low
None
None
TeamPass before 3.1.3.1 does not properly prevent a user from acting with the privileges of a different user_id. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
3.0.10
3.1.0
3.1.1
Fixed in
3.1.3.1
References
Updated Dec 30, 2024 · Source: OSV.dev
CVE-2024-50701
GHSA-2697-96mv-3gfm
Dec 30, 2024
TeamPass does not properly check whether a folder is in a user's allowed folders list
Medium
Network
Low
Low
None
TeamPass before 3.1.3.1, when retrieving information about access rights for a folder, does not properly check whether a folder is in a user's allowed folders list that has been defined by an admin. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
3.0.10
3.1.0
3.1.1
Fixed in
3.1.3.1
References
Updated Dec 30, 2024 · Source: OSV.dev
CVE-2023-3565
GHSA-524r-w8fx-hqg3
Jul 10, 2023
TeamPass Cross-site Scripting vulnerability
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Cross-site Scripting (XSS) - Generic in GitHub repository nilsteampassnet/teampass prior to 3.0.10. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.10
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3553
GHSA-2rhg-hqq9-8xjh
Jul 08, 2023
TeamPass information exposure vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
TeamPass prior to 3.0.10 allows unauthenticated actors to view application-specific and user data and files by viewing an endpoint directory listing. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.10
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3552
GHSA-2cv5-qvq3-6276
Jul 08, 2023
TeamPass vulnerable to Improper Encoding or Escaping of Output
7.6
/ 10
High
Network
Low
Low
Required
Changed
High
Low
None
TeamPass prior to 3.0.10 is vulnerable to cross-site scripting filter bypass in folder names. This can lead to information disclosure. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.10
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3551
GHSA-97hm-2mfr-2p97
Jul 08, 2023
TeamPass Code Injection vulnerability
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Code Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.10. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.10
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3531
GHSA-pwrw-g29q-3mp8
Jul 06, 2023
TeamPass Cross-site Scripting vulnerability
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.10. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.10
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3191
GHSA-qmw8-x364-xxxm
Jun 10, 2023
Teampass Cross-site Scripting vulnerability
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In versions of nilsteampassnet/teampass prior to 3.0.9 some user input was not properly sanitized which may have lead to stored cross-site scripting (XSS) vectors in the application. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.9
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3190
GHSA-p7xm-g427-jxfc
Jun 10, 2023
Teampass Cross-site Scripting vulnerability
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
In versions of nilsteampassnet/teampass prior to 3.0.9 some user input was not properly sanitized which may have lead to stored cross-site scripting (XSS) vectors in the application. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.9
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3095
GHSA-g3jr-6vj4-3x82
Jun 04, 2023
TeamPass vulnerable to Improper Access Control
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Improper Access Control in GitHub repository nilsteampassnet/teampass prior to 3.0.9. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.9
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3086
GHSA-j245-v2mh-5h6f
Jun 03, 2023
TeamPass vulnerable to stored Cross-site Scripting
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.9
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3084
GHSA-8vm8-38pc-8xhh
Jun 03, 2023
TeamPass vulnerable to stored Cross-site Scripting
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.9
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3083
GHSA-c6fv-3jm9-6r8f
Jun 03, 2023
TeamPass vulnerable to stored Cross-site Scripting
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.9
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-3009
GHSA-h5g9-2p35-54c7
May 31, 2023
nilsteampassnet/teampass vulnerable to cross-site scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. This enables an attacker to inject malicious code into a shared folder, which can then be executed by other users who have access to the folder. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.9
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-2859
GHSA-h6jh-cf83-qcq5
May 24, 2023
Code injection in nilsteampassnet/teampass
7.1
/ 10
High
Network
Low
None
Required
Unchanged
Low
High
None
nilsteampassnet/teampass prior to 3.0.9 is vulnerable to code injection. A malicious user could potentially rename a folder with a payload containing malicious code. This could result in an attack on an admin who edits the folder, as the payload could execute upon the admin's interaction with the folder. This attack could potentially allow the attacker to gain unauthorized access to the admin's system or steal sensitive information, or it could force admin to get redirected to a website controlled by the attacker. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.9
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-2591
GHSA-prj5-2g2p-x2mw
May 09, 2023
teampass vulnerable to code injection
7.1
/ 10
High
Network
Low
None
Required
Unchanged
Low
High
None
In nilsteampassnet/teampass prior to 3.0.7, if two users have the same folder access, malicious users can create an item where its label field is vulnerable to HTML injection. When other users see that item, it may force them to redirect to the attacker's website or capture their data using a form. The issue is fixed in version 3.0.7. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.7
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-2516
GHSA-2ffp-w665-9mgx
May 05, 2023
Cross Site Scripting in nilsteampassnet/teampass
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
nilsteampassnet/teampass prior to version 3.0.7 is vulnerable to cross site scripting (XSS) from item names within a folder. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.7
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-2021
GHSA-4h2q-84w7-4mhx
Apr 13, 2023
nilsteampassnet/teampass vulnerable to stored cross-site scripting (XSS)
5.8
/ 10
Medium
Local
High
None
Required
Unchanged
High
Low
Low
nilsteampassnet/teampass prior to 3.0.3 is vulnerable to stored cross-site scripting (XSS) in the description parameter of a folder. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.3
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-1545
GHSA-ppxm-q2h4-v7mm
Mar 21, 2023
Teampass SQL Injection vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
SQL Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.0.22. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.0.22
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-1463
GHSA-86jq-pwgx-6vrq
Mar 17, 2023
Improper Authorization in nilsteampassnet/teampass
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
Low
Improper Authorization in GitHub repository nilsteampassnet/teampass prior to 3.0.0.23. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.0.23
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-1070
GHSA-x36g-4629-xp9v
Feb 27, 2023
TeamPass External Control of File Name or Path vulnerability
7.1
/ 10
High
Network
Low
Low
None
Unchanged
None
Low
High
External Control of File Name or Path in GitHub repository nilsteampassnet/teampass prior to 3.0.0.22. Affected versions
2.1.21
2.1.26
2.1.27
3.0.0
3.0.0.10
3.0.0.11
Fixed in
3.0.0.23
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2019-16904
GHSA-rpmr-fwh5-24fm
May 24, 2022
TeamPass Cross-site Scripting (XSS) vulnerability
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
TeamPass 2.1.27.36 allows XSS by setting a crafted password for an item in a folder, and then sharing that item with an admin. (The crafted password is exploitable when viewing the change history, or the previous used password field.) Affected versions
2.1.21
2.1.26
2.1.27
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2020-12479
GHSA-6jf9-8m34-96w5
May 24, 2022
TeamPass PHP arbitrary file include vulnerability
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
TeamPass 2.1.27.36 allows any authenticated TeamPass user to trigger a PHP file include vulnerability via a crafted HTTP request with sources/users.queries.php newValue directory traversal. Affected versions
2.1.21
2.1.26
2.1.27
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2019-17205
GHSA-v969-5v7f-pmg2
May 24, 2022
TeamPass Stored Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
TeamPass 2.1.27.36 allows Stored XSS by placing a payload in the username field during a login attempt. When an administrator looks at the log of failed logins, the XSS payload will be executed. Affected versions
2.1.21
2.1.26
2.1.27
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2019-17204
GHSA-qx37-225j-qr89
May 24, 2022
TeamPass Stored Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
TeamPass 2.1.27.36 allows Stored XSS by setting a crafted Knowledge Base label and adding any available item. Affected versions
2.1.21
2.1.26
2.1.27
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2019-17203
GHSA-pqx8-q35p-pgcv
May 24, 2022
TeamPass Stored Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
TeamPass 2.1.27.36 allows Stored XSS at the Search page by setting a crafted password for an item in any folder. Affected versions
2.1.21
2.1.26
2.1.27
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2019-12950
GHSA-m3pp-jcpm-2vr9
May 24, 2022
TeamPass Cross-site Scripting (XSS)
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
An issue was discovered in TeamPass 2.1.27.35. From the sources/items.queries.php "Import items" feature, it is possible to load a crafted CSV file with an XSS payload. Affected versions
2.1.21
2.1.26
2.1.27
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2015-7564
GHSA-r64j-5w3w-fp49
May 17, 2022
TeamPass vulnerable to SQL Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Multiple SQL injection vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in an action_on_quick_icon action to item.query.php or the (2) order or (3) direction parameter in an (a) connections_logs, (b) errors_logs or (c) access_logs action to view.query.php. Affected versions
2.1.21
Fixed in
2.1.25
References Updated Apr 22, 2025 · Source: OSV.dev
CVE-2015-7562
GHSA-48q3-m4hf-56c9
May 17, 2022
TeamPass vulnerable to Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Multiple cross-site scripting (XSS) vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) label value of an item or (2) name of a role. Affected versions
2.1.21
Fixed in
2.1.25
References Updated Apr 22, 2025 · Source: OSV.dev
CVE-2017-9436
GHSA-cm26-gp8j-w6xf
May 17, 2022
TeamPass SQL injection in users.queries.php
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
TeamPass before 2.1.27.5 is vulnerable to a SQL injection in users.queries.php. Affected versions
2.1.21
2.1.26
2.1.27
Fixed in
2.1.27.5
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2017-15278
GHSA-28pv-2j2h-fmhc
May 17, 2022
TeamPass Cross-Site Scripting (XSS)
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Cross-Site Scripting (XSS) was discovered in TeamPass before 2.1.27.9. The vulnerability exists due to insufficient filtration of data (in /sources/folders.queries.php). An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website. Affected versions
2.1.21
2.1.26
2.1.27
Fixed in
2.1.27.9
References
Updated Apr 24, 2024 · Source: OSV.dev
CVE-2017-15051
GHSA-r68m-4v39-cf43
May 17, 2022
TeamPass stored cross-site scripting (XSS) vulnerability
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Multiple stored cross-site scripting (XSS) vulnerabilities in TeamPass before 2.1.27.9 allow authenticated remote attackers to inject arbitrary web script or HTML via the (1) URL value of an item or (2) user log history. To exploit the vulnerability, the attacker must be first authenticated to the application. For the first one, the attacker has to simply inject XSS code within the URL field of a shared item. For the second one however, the attacker must prepare a payload within its profile, and then ask an administrator to modify its profile. From there, whenever the administrator accesses the log, it can be XSS'ed. Affected versions
2.1.21
2.1.26
2.1.27
Fixed in
2.1.27.9
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2017-15054
GHSA-rm3q-qfrm-frrv
May 17, 2022
TeamPass arbitrary file upload vulnerability
7.5
/ 10
High
Network
High
Low
None
Unchanged
High
High
High
An arbitrary file upload vulnerability, present in TeamPass before 2.1.27.9, allows remote authenticated users to upload arbitrary files leading to Remote Command Execution. To exploit this vulnerability, an authenticated attacker has to tamper with parameters of a request to upload.files.php, in order to select the correct branch and be able to upload any arbitrary file. From there, it can simply access the file to execute code on the server. Affected versions
2.1.21
2.1.26
2.1.27
Fixed in
2.1.27.9
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2017-15055
GHSA-7ghm-6p42-h226
May 13, 2022
TeamPass Improper Privilege Management
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
TeamPass before 2.1.27.9 does not properly enforce item access control when requesting items.queries.php. It is then possible to copy any arbitrary item into a directory controlled by the attacker, edit any item within a read-only directory, delete an arbitrary item, delete the file attachments of an arbitrary item, copy the password of an arbitrary item to the copy/paste buffer, access the history of an arbitrary item, and edit attributes of an arbitrary directory. To exploit the vulnerability, an authenticated attacker must tamper with the requests sent directly, for example by changing the "item_id" parameter when invoking "copy_item" on items.queries.php. Affected versions
2.1.21
2.1.26
2.1.27
Fixed in
2.1.27.9
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2017-15052
GHSA-5qr3-4839-88gf
May 13, 2022
TeamPass Improper Privilege Management
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
None
TeamPass before 2.1.27.9 does not properly enforce manager access control when requesting users.queries.php. It is then possible for a manager user to delete an arbitrary user (including admin), or modify attributes of any arbitrary user except administrator. To exploit the vulnerability, an authenticated attacker must have the manager rights on the application, then tamper with the requests sent directly, for example by changing the "id" parameter when invoking "delete_user" on users.queries.php. Affected versions
2.1.21
2.1.26
2.1.27
Fixed in
2.1.27.9
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2017-15053
GHSA-xvjf-394g-phrr
May 13, 2022
TeamPass Improper Privilege Management
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
None
TeamPass before 2.1.27.9 does not properly enforce manager access control when requesting roles.queries.php. It is then possible for a manager user to modify any arbitrary roles within the application, or delete any arbitrary role. To exploit the vulnerability, an authenticated attacker must have the manager rights on the application, then tamper with the requests sent directly, for example by changing the "id" parameter when invoking "delete_role" on roles.queries.php. Affected versions
2.1.21
2.1.26
2.1.27
Fixed in
2.1.27.9
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2019-1000001
GHSA-q9qr-h33g-fw3j
May 13, 2022
TeamPass Storing Passwords in a Recoverable Format vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
TeamPass version 2.1.27 and earlier contains a Storing Passwords in a Recoverable Format vulnerability in Shared password vaults that can result in all shared passwords are recoverable server side. This attack appears to be exploitable via any vulnerability that can bypass authentication or role assignment and can lead to shared password leakage. Affected versions
2.1.21
2.1.26
2.1.27
References Updated Apr 24, 2024 · Source: OSV.dev
CVE-2022-26980
GHSA-m2wv-m5pf-284r
Mar 29, 2022
Cross-site Scripting in teampass
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Teampass 2.1.26 allows reflected XSS via the index.php PATH_INFO. Someone must open a link for the Teampass Password Manager index page containing malicious payload. Affected versions
2.1.21
2.1.26
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-11671
GHSA-gmr7-m73x-6c9q
Jul 26, 2021
Missing Authorization in TeamPass
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Lack of authorization controls in REST API functions in TeamPass through 2.1.27.36 allows any TeamPass user with a valid API token to become a TeamPass administrator and read/modify all passwords via authenticated api/index.php REST API calls. NOTE: the API is not available by default. Affected versions
2.1.21
2.1.26
2.1.27
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-12477
GHSA-fv48-hjhp-94c7
Jul 26, 2021
Incorrect Authorization in TeamPass
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
The REST API functions in TeamPass 2.1.27.36 allow any user with a valid API token to bypass IP address whitelist restrictions via an X-Forwarded-For client HTTP header to the getIp function. Affected versions
2.1.21
2.1.26
2.1.27
References Updated Nov 08, 2023 · Source: OSV.dev |